★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/server_security_article-900.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
 
News: Server Security 6/16/2000 18:09

BIND 8.2.x Overflow Vulnerability

CIAC
Posted By: Benjamin D. Thomas
6/16/2000

Here is an information bulletin that was issues by CIAC last Tuesday. It covers a BIND buffer overflow that exists in 8.2, 8.2.1 and 8.2.2. Here CIAC explains how the exploit works, "The exploit requires two systems to be successful. The first is a DNS server that will have an altered DNS table. The second machine is where the attack will take place."

Intruders alter a valid DNS server's (we will call this box [SERVER 1]) lookup table to point toward their computer [HACKER.COM] as the Authoritative Name Server for that domain. Intruders then prompt your DNS server to resolve [HACKER.COM]. [SERVER 1] passes the information back to your DNS server for the Authoritative Name Server for . Your DNS server then goes to [HACKER.COM] looking to complete the query. Once your DNS server queries [HACKER.COM] for resolution, BIND runs and the buffer overflow condition occurs.

Once the buffer overflow is executed, the following command is executed in the source code obtained by CIAC: cd /; uname -a; pwd; id;. The named service will crash as a result of the buffer overflow.


Click here to go to this article.

Know your enemy
Apr 28

Start your day with a cup of DoS
Apr 28

Increased Internet Attacks Against U.S. Web Sites and Mail Servers Possible in Early May
Apr 28

DeCSS code-crack dispute back in court
Apr 27

Linux Network Security: Introduction
Apr 27

Analysis of lpdw0rm Affecting Red Hat 7 Systems
Apr 27

Companies hit by hackers fight back
Apr 27

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000